{"id":13331,"date":"2016-04-28T20:40:52","date_gmt":"2016-04-28T18:40:52","guid":{"rendered":"https:\/\/hetzner.co.za\/help-centre\/?p=13331"},"modified":"2025-12-30T09:58:54","modified_gmt":"2025-12-30T07:58:54","slug":"joomla-security","status":"publish","type":"post","link":"https:\/\/xneelo.co.za\/help-centre\/website\/joomla-security\/","title":{"rendered":"Joomla Security"},"content":{"rendered":"<h2>Tips to Secure Your Joomla Website<\/h2>\n<p><span style=\"font-weight: 400;\">We are responsible for server administration and the security of its network. As a customer of ours, you are responsible for the administration and security of your website. <\/span><b>Outdated versions of Joomla installations, themes &amp; plugins could result in your website being attacked. <\/b><\/p>\n<p><span style=\"font-weight: 400;\">Joomla\u2019s wide availability makes it an appealing target for intruders. <\/span>We\u2019d like to provide you with security tips so that you can secure your Joomla website against vulnerabilities.<\/p>\n<p><span style=\"font-weight: 400;\">Vulnerabilities are what makes your website susceptible to intrusions from outsiders with malicious intent.<\/span><b>\u00a0<\/b><\/p>\n<h3>1. Keep your site updated<\/h3>\n<p><span style=\"font-weight: 400;\">All Joomla sites and extensions should be checked regularly for issues and updates. Older versions of Joomla are not maintained with security updates. <\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Apply core Joomla updates as soon as they\u2019re released. <\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Use the <a href=\"https:\/\/downloads.joomla.org\/latest\" target=\"_blank\" rel=\"noopener noreferrer\">latest Joomla security update<\/a>.<\/span><\/li>\n<\/ul>\n<h3><span style=\"font-weight: 400;\">2. Carefully choose which themes and plugins you download <\/span><\/h3>\n<p><span style=\"font-weight: 400;\">It only takes one plugin or template to make you vulnerable.<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Keep them updated and don\u2019t use pirated plugins. <\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Delete the Joomla templates you aren&#8217;t using.<\/span><\/li>\n<\/ul>\n<h3><span style=\"font-weight: 400;\">3. Use a very strong password<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">A strong password protects your website content and prevents intruders from gaining access to your admin account, where they can install malicious scripts that can potentially compromise your entire website. Many potential vulnerabilities can be avoided with a strong password. <\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Make sure you use a strong password for <a href=\"https:\/\/xneelo.co.za\/help-centre\/website\/how-to-change-your-ftp-password\/\" target=\"_blank\" rel=\"noopener noreferrer\">FTP passwords<\/a>, Joomla login passwords and <a href=\"https:\/\/xneelo.co.za\/help-centre\/website\/how-to-change-your-database-password-via-the-xneelo-control-panel\/\" target=\"_blank\" rel=\"noopener noreferrer\">database passwords.<\/a><\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Should your domain be compromised, it\u2019s advisable you change all passwords relating to that domain.<\/span><\/li>\n<\/ul>\n<h3><span style=\"font-weight: 400;\">4. Install security-related plugins<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">Carefully choose a Joomla security plugin that will protect your website. For example, plugins that block incorrect logins, notify you of new edits and warn you when your site is vulnerable to attack.<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Install a <a href=\"http:\/\/extensions.joomla.org\/category\/access-a-security\/site-security\" target=\"_blank\" rel=\"noopener noreferrer\">trusted security plugin<\/a>. Use the plugin user ratings as a guide.<\/span><\/li>\n<\/ul>\n<h3><span style=\"font-weight: 400;\">5. Avoid using default configurations<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">Changing your default settings adds another thin layer of protection against intruders. In Joomla the default name for the Super Administrator is \u201cadmin\u201d and most intruders know this. <\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Delete the default admin and create a new custom login.<\/span><\/li>\n<\/ul>\n<h3><span style=\"font-weight: 400;\">6. Make backups<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">Before you delete anything, make a full backup of your site. Our backups are only intended for disaster recovery purposes. <\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">We recommend that you regularly perform your own backups.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Backup your data on read-only media, to ensure your data has not been tampered with.<\/span><\/li>\n<\/ul>\n<p><b>Should your website be compromised<\/b><span style=\"font-weight: 400;\">, Joomla developers recommend setting a <a href=\"https:\/\/vel.joomla.org\/articles\/224-safe-route-to-recovery%20(recover%20once%20hacked)\" target=\"_blank\" rel=\"noopener noreferrer\">safe route to the recovery<\/a> of your website. Note, this process could take your site offline for about 15 minutes.<\/span><\/p>\n<p><em>For further information see:<\/em><\/p>\n<ul>\n<li>Latest security update: <a href=\"https:\/\/downloads.joomla.org\/latest\" target=\"_blank\" rel=\"noopener noreferrer\">joomlasecurity.org<\/a><\/li>\n<li>Security Checklist: <a href=\"https:\/\/docs.joomla.org\/Security_Checklist\/Joomla!_Setup\" target=\"_blank\" rel=\"noopener noreferrer\">joomla.org<\/a><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n","protected":false,"plain":"<h2>Tips to Secure Your Joomla Website<\/h2>\r\n<span >We are responsible for server administration and the security of its network. As a customer of ours, you are responsible for the administration and security of your website. <\/span><b>Outdated versions of Joomla installations, themes &amp; plugins could result in your website being attacked. <\/b>\r\n\r\n<span >Joomla\u2019s wide availability makes it an appealing target for intruders. <\/span>We\u2019d like to provide you with security tips so that you can secure your Joomla website against vulnerabilities.\r\n\r\n<span >Vulnerabilities are what makes your website susceptible to intrusions from outsiders with malicious intent.<\/span><b>\u00a0<\/b>\r\n<h3>1. Keep your site updated<\/h3>\r\n<span >All Joomla sites and extensions should be checked regularly for issues and updates. Older versions of Joomla are not maintained with security updates. <\/span>\r\n<ul>\r\n \t<li ><span >Apply core Joomla updates as soon as they\u2019re released. <\/span><\/li>\r\n \t<li ><span >Use the <a href=\"https:\/\/downloads.joomla.org\/latest\" target=\"_blank\" rel=\"noopener noreferrer\">latest Joomla security update<\/a>.<\/span><\/li>\r\n<\/ul>\r\n<h3><span >2. Carefully choose which themes and plugins you download <\/span><\/h3>\r\n<span >It only takes one plugin or template to make you vulnerable.<\/span>\r\n<ul>\r\n \t<li ><span >Keep them updated and don\u2019t use pirated plugins. <\/span><\/li>\r\n \t<li ><span >Delete the Joomla templates you aren't using.<\/span><\/li>\r\n<\/ul>\r\n<h3><span >3. Use a very strong password<\/span><\/h3>\r\n<span >A strong password protects your website content and prevents intruders from gaining access to your admin account, where they can install malicious scripts that can potentially compromise your entire website. Many potential vulnerabilities can be avoided with a strong password. <\/span>\r\n<ul>\r\n \t<li ><span >Make sure you use a strong password for <a href=\"https:\/\/xneelo.co.za\/help-centre\/website\/how-to-change-your-ftp-password\/\" target=\"_blank\" rel=\"noopener noreferrer\">FTP passwords<\/a>, Joomla login passwords and <a href=\"https:\/\/xneelo.co.za\/help-centre\/website\/how-to-change-your-database-password-via-the-xneelo-control-panel\/\" target=\"_blank\" rel=\"noopener noreferrer\">database passwords.<\/a><\/span><\/li>\r\n \t<li ><span >Should your domain be compromised, it\u2019s advisable you change all passwords relating to that domain.<\/span><\/li>\r\n<\/ul>\r\n<h3><span >4. Install security-related plugins<\/span><\/h3>\r\n<span >Carefully choose a Joomla security plugin that will protect your website. For example, plugins that block incorrect logins, notify you of new edits and warn you when your site is vulnerable to attack.<\/span>\r\n<ul>\r\n \t<li ><span >Install a <a href=\"http:\/\/extensions.joomla.org\/category\/access-a-security\/site-security\" target=\"_blank\" rel=\"noopener noreferrer\">trusted security plugin<\/a>. Use the plugin user ratings as a guide.<\/span><\/li>\r\n<\/ul>\r\n<h3><span >5. Avoid using default configurations<\/span><\/h3>\r\n<span >Changing your default settings adds another thin layer of protection against intruders. In Joomla the default name for the Super Administrator is \u201cadmin\u201d and most intruders know this. <\/span>\r\n<ul>\r\n \t<li ><span >Delete the default admin and create a new custom login.<\/span><\/li>\r\n<\/ul>\r\n<h3><span >6. Make backups<\/span><\/h3>\r\n<span >Before you delete anything, make a full backup of your site. Our backups are only intended for disaster recovery purposes. <\/span>\r\n<ul>\r\n \t<li ><span >We recommend that you regularly perform your own backups.<\/span><\/li>\r\n \t<li ><span >Backup your data on read-only media, to ensure your data has not been tampered with.<\/span><\/li>\r\n<\/ul>\r\n<b>Should your website be compromised<\/b><span >, Joomla developers recommend setting a <a href=\"https:\/\/vel.joomla.org\/articles\/224-safe-route-to-recovery%20(recover%20once%20hacked)\" target=\"_blank\" rel=\"noopener noreferrer\">safe route to the recovery<\/a> of your website. Note, this process could take your site offline for about 15 minutes.<\/span>\r\n\r\n<em>For further information see:<\/em>\r\n<ul>\r\n \t<li>Latest security update: <a href=\"https:\/\/downloads.joomla.org\/latest\" target=\"_blank\" rel=\"noopener noreferrer\">joomlasecurity.org<\/a><\/li>\r\n \t<li>Security Checklist: <a href=\"https:\/\/docs.joomla.org\/Security_Checklist\/Joomla!_Setup\" target=\"_blank\" rel=\"noopener noreferrer\">joomla.org<\/a><\/li>\r\n<\/ul>\r\n&nbsp;"},"excerpt":{"rendered":"<p>Tips to help secure your Joomla website against vulnerabilities.<\/p>\n","protected":false},"author":7,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"lsx_disable_title":"0","_relevanssi_hide_post":"","_relevanssi_hide_content":"","_relevanssi_pin_for_all":"","_relevanssi_pin_keywords":"","_relevanssi_unpin_keywords":"","_relevanssi_related_keywords":"","_relevanssi_related_include_ids":"","_relevanssi_related_exclude_ids":"","_relevanssi_related_no_append":"","_relevanssi_related_not_related":"","_relevanssi_related_posts":"","_relevanssi_noindex_reason":"","footnotes":""},"categories":[166,188],"tags":[17432,479],"topics":[10377],"class_list":["post-13331","post","type-post","status-publish","format-standard","hentry","category-website","category-website-security","tag-joomla","tag-security","topics-website-security"],"acf":[],"additional_meta":{"category_title":[{"term_id":166,"name":"Website","slug":"website","term_group":0,"term_taxonomy_id":166,"taxonomy":"category","description":"About your Website(s)","parent":0,"count":169,"filter":"raw","term_order":"120","cat_ID":166,"category_count":169,"category_description":"About your Website(s)","cat_name":"Website","category_nicename":"website","category_parent":0},{"term_id":188,"name":"Website Security","slug":"website-security","term_group":0,"term_taxonomy_id":188,"taxonomy":"category","description":"Securing your website","parent":168,"count":15,"filter":"raw","term_order":"122","cat_ID":188,"category_count":15,"category_description":"Securing your website","cat_name":"Website Security","category_nicename":"website-security","category_parent":168}],"tag_title":[{"term_id":17432,"name":"joomla","slug":"joomla","term_group":0,"term_taxonomy_id":17432,"taxonomy":"post_tag","description":"","parent":0,"count":2,"filter":"raw","term_order":"2318"},{"term_id":479,"name":"security","slug":"security","term_group":0,"term_taxonomy_id":479,"taxonomy":"post_tag","description":"","parent":0,"count":5,"filter":"raw","term_order":"2670"}]},"featured_image_src":null,"author_info":{"display_name":"marketing","author_link":"https:\/\/xneelo.co.za\/help-centre\/author\/marketing\/","author_avatar":"https:\/\/secure.gravatar.com\/avatar\/a6ea315e112423b2b955cb020fbce2b0835956c6ad85ff0f13f1db298977eaaa?s=96&d=mm&r=g"},"_links":{"self":[{"href":"https:\/\/xneelo.co.za\/help-centre\/wp-json\/wp\/v2\/posts\/13331","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/xneelo.co.za\/help-centre\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/xneelo.co.za\/help-centre\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/xneelo.co.za\/help-centre\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/xneelo.co.za\/help-centre\/wp-json\/wp\/v2\/comments?post=13331"}],"version-history":[{"count":0,"href":"https:\/\/xneelo.co.za\/help-centre\/wp-json\/wp\/v2\/posts\/13331\/revisions"}],"wp:attachment":[{"href":"https:\/\/xneelo.co.za\/help-centre\/wp-json\/wp\/v2\/media?parent=13331"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/xneelo.co.za\/help-centre\/wp-json\/wp\/v2\/categories?post=13331"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/xneelo.co.za\/help-centre\/wp-json\/wp\/v2\/tags?post=13331"},{"taxonomy":"topics","embeddable":true,"href":"https:\/\/xneelo.co.za\/help-centre\/wp-json\/wp\/v2\/topics?post=13331"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}